This change was made because the advice was "out of date" and Google handles JavaScript fine.
A developer-targeting campaign leveraged malicious Next.js repositories to trigger a covert RCE-to-C2 chain through standard ...